Cloud, Infrastructure and DevSecOps Cloud security: the 5 configuration mistakes we see most often
Most cloud breaches don't come from the provider's flaws, but from the customer's misconfiguration. Here are the five most common traps.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Cloud, Infrastructure and DevSecOps Most cloud breaches don't come from the provider's flaws, but from the customer's misconfiguration. Here are the five most common traps.
Supply Chain Security In May 2026 the Mini Shai-Hulud worm hit npm and PyPI at once, stealing CI/CD secrets. We analyse the attack and how to harden your pipeline.
Human Security Your phone knows more about you than your computer. Twelve practical settings and habits that genuinely protect your data, accounts and privacy.
AI Security Confidential computing for AI explained: understand TEEs, remote attestation, key release, trust boundaries, deployment patterns, and real limits.
Human Security Remote work is here to stay — and with it company data on home networks and private hardware. A practical standard: devices, access, Wi-Fi.
AI Security Understand model extraction, membership inference, inversion, and training-data leakage, then build layered protection for AI models and data.
Human Security Impersonations of OLX and Vinted are among the most reported scams in Poland. We explain the 'safe payment' mechanism that actually robs the seller.
Penetration Testing and AppSec Insecure deserialization in Java, .NET, and Python: identify trust boundaries, test without unsafe gadget chains, and remove the root cause of RCE.
Penetration Testing and AppSec Active Directory is the top target once inside a network. We cover common attack paths — Kerberoasting, excessive privileges — and how to close them.
Human Security Ads promise a VPN gives anonymity and total security. We explain what a VPN really does, what it doesn't protect against and when it's worth using.
Threats and Incidents What to do when a data breach happens — from confirming the incident, through limiting the impact, to GDPR obligations.
Penetration Testing and AppSec Understand prototype pollution in JavaScript and Node.js, trace pollution sources and gadgets, test safely, and harden applications effectively.
Penetration Testing and AppSec Learn how web race conditions and TOCTOU flaws break business logic, how to test concurrency safely, and which atomic controls actually fix them.
Identity and Access Shared passwords in a spreadsheet are a ticking bomb. How a business password manager works, how to choose one and roll it out to teams.
Threats and Incidents Engineer reliable Sigma rules for SIEM: hypotheses, logsource contracts, correlation, filters, backend tests, tuning, metrics and purple-team validation.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.